Add/Remove works again, thanks for that. Here are the logs. Qoologic first.
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
»»»»»»»»»»»»»»»»»»»»»»»»» Files found in System »»»»»»»»»»»»»»»»»»»»»»»
* qoologic C:\WINDOWS\VAVOM.DLL
* qoologic C:\WINDOWS\INSTAL~1.EXE
* qoologic C:\WINDOWS\UNADBEH.EXE
* urllogic C:\WINDOWS\VAVOM.DLL
* ad-beh C:\WINDOWS\BPBISET.DLL
* ad-beh C:\WINDOWS\QNQKD.DLL
* ad-beh C:\WINDOWS\INSTAL~1.EXE
* ad-beh C:\WINDOWS\UNADBEH.EXE
* ad-beh C:\WINDOWS\QCQNDXB.EXE
* ad-beh C:\WINDOWS\system\WINUP2~1.DLL
* ad-beh C:\WINDOWS\system\WMCONFIG.CPL
* ad-beh C:\WINDOWS\system\WMCONFIG.CPL
»»»»»»»»»»»»»»»»»»»»»»»»» startup files »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»
Global Startup:
problem locating dir
User Startup:
C:\WINDOWS\Start Menu\Programs\StartUp
»»»»»»»»»»»»»»»»»»»»»»»»» Active setup »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
"Find activesetup", version1, launched at: 14:27
Operating System: Windows 98
HKLM\Software\Microsoft\Active Setup\Installed Components\
"{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\(Default)" = "Microsoft Outlook Express 5"
\StubPath = ""C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:IE50 /user /uninstall" [MS]
SpSeHjfix.exe saved to My Documents-
(5/9/05 2:09:06 PM) SPSeHjFix started v1.09
(5/9/05 2:09:06 PM) OS: Win98SE A (4.10.67766446)
(5/9/05 2:09:06 PM) Language: english
(5/9/05 2:09:11 PM) Disinfect started
(5/9/05 2:09:11 PM) Bad-Dll(IEP): se.dll
(5/9/05 2:09:11 PM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\SYSTEM\BGFJM.DLL
(5/9/05 2:09:11 PM) Searchassistant Uninstaller - Keys Deleted
(5/9/05 2:09:11 PM) UBF: 6
(5/9/05 2:09:11 PM) UBB: 0
(5/9/05 2:09:11 PM) FilterKey: HKCR\text/html (deleted)
(5/9/05 2:09:11 PM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(5/9/05 2:09:11 PM) FilterKey: HKCR\CLSID\{075561CA-C090-11D9-9783-BBE4C76007EE} (deleted)
(5/9/05 2:09:11 PM) FilterKey: HKCR\text/plain (deleted)
(5/9/05 2:09:11 PM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(5/9/05 2:09:11 PM) FilterKey: HKCR\CLSID\{075561CA-C090-11D9-9783-BBE4C76007EE} (error while deleting)
(5/9/05 2:09:11 PM) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{29761890-C08C-11D9-9783-BBE45A7B6978} (deleted)
(5/9/05 2:09:11 PM) BHO-Key: HKCR\CLSID\{29761890-C08C-11D9-9783-BBE45A7B6978} (deleted)
(5/9/05 2:09:11 PM) UBR: 10
(5/9/05 2:09:11 PM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall (deleted)
(5/9/05 2:09:11 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://C:\WINDOWS\TEMP\se.dll/sp.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://C:\WINDOWS\TEMP\se.dll/sp.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(5/9/05 2:09:11 PM) Stealth-String found: C:\WINDOWS\READM_X2.HTZ
(5/9/05 2:09:11 PM) File added to delete: c:\windows\system\bgfjm.dll
(5/9/05 2:09:11 PM) File added to delete: c:\windows\system\bgfjm.dll
(5/9/05 2:09:11 PM) File added to delete: c:\windows\temp\se.dll
(5/9/05 2:09:11 PM) File added to delete: c:\windows\readm_x2.htz
(5/9/05 2:09:12 PM) Reboot
SpSeHjfix.exe 2nd run-
(5/9/05 2:18:33 PM) SPSeHjFix 2nd Step
(5/9/05 2:18:33 PM) RunServicesOnce-Key: (edited)
(5/9/05 2:18:38 PM) Cleaned
Fresh HJT log-
Logfile of HijackThis v1.99.1
Scan saved at 3:51:46 PM, on 5/10/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MM_TRAY.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLDIAL.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\SYSTEM\PICSVR\PICSVR.EXE
C:\PROGRAM FILES\SONIQUE\SQSTART.EXE
C:\PROGRAM FILES\AMERICA ONLINE 9.0\AOLTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\PROGRAM FILES\AMERICA ONLINE 9.0\WEmail RemovedEXE
C:\PROGRAM FILES\AMERICA ONLINE 9.0\SHELLMON.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\AOLTPSPD.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HIJACK THIS\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [System Sentry] C:\PROGRA~1\EASYDE~1\SYSTEM~1\Protect.exe protect
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\SYSTEM\PICSVR\PICSVR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SoniqueQuickStart] C:\Program Files\Sonique\sqstart.exe -nostick
O4 - Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Startup: WinZip Quick Pick.lnk.disabled
O4 - Startup: America Online 9.0 Tray Icon.lnk.disabled
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL/SEARCH.HTML
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE (file missing)
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.Email Removed
O15 - Trusted IP range: 206.161.125.149
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMesse...pDownloader.cabO17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net